DCC Level 1: The Assessment Process, Step by Step
For suppliers in the UK Ministry of Defence (MOD) supply chain, Defence Cyber Certification (DCC) Level 1 is typically the level required where a contract carries a low, but not negligible, level of assessed cyber risk. It sits above the self-assessed Level 0, and below Levels 2 and 3, which require independent, evidence-based verification through a Certification Body (CB).
Unlike Level 0, a short self-assessment completed entirely through the IASME portal, Level 1 moves to a full evidence-based review. You complete an Assessment Submission Record (ASR) covering 101 controls, and a Periculo assessor reviews your responses and evidence before certification is decided. It's a bigger step up than the jump from nothing to Level 0, so it's worth knowing exactly what the process looks like before you start.
Here's what to expect, split into what's on you to prepare, and what happens once your assessor takes over.
Understanding DCC Level 1
DCC assesses your organisation against DEFSTAN 05-138 Issue 4, the defence cyber security standard that underpins the whole scheme. Level 1 requires a valid Cyber Essentials (CE) certificate as a prerequisite. Cyber Essentials Plus isn't required until Level 2. If you don't already hold CE, this needs to be in place, with a scope that overlaps your intended DCC scope, before your Level 1 assessment can proceed.
Certification is valid for three years, with a short annual attestation to keep it live in between, the same renewal pattern as Level 0.
Before the Audit: What You Need to Do
These four steps are yours to work through before your assessor gets involved in earnest.
Step 1: Get Your Scope Right First
Scope is, by IASME's own guidance, the single most important part of the DCC process, and an under-scoped assessment fails automatically, no matter how well-controlled the systems you did include actually are.
DCC scope is broader than your Cyber Essentials scope. CE only covers internet-connected devices: laptops, desktops, servers, cloud services. DCC covers the whole organisation: every process, system and business function needed to operate and deliver securely, including non-internet-connected systems such as operational technology (OT), industrial control systems, building entry systems, or environmental controls, where these are essential to how you operate.
Before you go further, define:
- The systems, services and business functions in scope
- Any explicit exclusions, and why they're excluded
- Confirmation that your CE scope sits within, or clearly overlaps, your DCC scope
You can complete Periculo's DCC scoping form to capture this, or bring your own documented Statement of Scope to your Certification Body.
Step 2: Confirm Your Cyber Essentials Certificate
Level 1 cannot proceed without a valid CE certificate whose scope overlaps your DCC scope. If you don't hold CE yet, this needs to be delivered as a separate engagement first; it isn't something that can run in parallel with your DCC Level 1 assessment.
If you already hold CE, your Certification Body will validate the certificate and check the scope overlap before onboarding you, but confirming it's current and correctly scoped is on you to do first.
Step 3: Engage a Certification Body and Agree Your Audit Dates
Once your scope and CE prerequisite are confirmed, engage an IASME-accredited Certification Body. They'll issue your Assessment Submission Record (ASR), the document you'll use to respond to all 101 Level 1 controls and set you up on a delivery ticket with an assigned assessor and key dates.
This is also the point to agree on your audit dates. Most assessments open with a kickoff call on day one, so it's worth having evidence gathering well underway before that date is booked.
Step 4: Complete the ASR and Gather Your Evidence
For each of the 101 controls, you'll need to:
- Provide a response describing how the control is met
- Reference supporting evidence against that response
- Generate and record hash values for every evidence file, so its integrity can be verified later
Your Certification Body won't draft responses for you; this is your organisation's evidence of its own controls, not the assessor's. Build this into a secure, access-controlled evidence folder, and share access with your assessor ahead of the audit date. Under scheme rules, this needs to be complete before the audit can go ahead.
During the Audit: What Your Assessor Does
Once your submission is in, the next four steps are largely out of your hands; your assessor leads, and you respond to what they find.
Step 1: Kickoff Call
The assessment proper begins with a kickoff call, where your assessor confirms scope, checks your submission is complete, and walks through the audit timetable.
Step 2: Theoretical Review and the Readiness Check
Your assessor reviews your ASR responses and evidence offline; this is the theoretical review. You'll get initial feedback, and any areas needing improvement are flagged early. Before moving to practical validation, your assessor runs a readiness check: if anything looks incomplete, unclear, or likely to trigger an automatic fail, you'll be given the chance to update your responses or evidence first. This exists precisely so you don't walk into practical scoring carrying an avoidable fail.
Step 3: Practical Validation
With the theoretical review complete, your assessor moves to practical validation, checking that what your evidence describes is actually true in practice. Depending on your environment, this might include:
- Screenshare demonstrations of specific controls
- Short interviews with control owners
- Sampling of endpoint encryption and patching status
- Review of incident response evidence
- Network boundary checks
Step 4: Scoring, Clarifications and Certification
All scoring is recorded against your ASR, with automatic-fail controls checked first. If your assessor raises non-conformities, these are worked through via your delivery ticket, on a remediation timeline you agree together; practical scoring can pause while this happens. Once scoring is finalised, your assessor signs off, the outcome is entered on the IASME platform, and your certificate is issued automatically through IASME.
After Certification: Keep Your Evidence
Certification isn't the end of your obligations. You're required to keep your evidence accessible to your Certification Body for two months after the assessment, and to retain the full evidence set for 3.5 years after certification. It's worth setting up a dedicated, access-controlled repository for this before you start, rather than scrambling to reconstruct it later, particularly with an annual attestation due every year of your three-year certificate.
Common Pitfalls to Avoid
- Under-scoping. Leaving out non-internet-connected systems that are essential to your operation is one of the most common causes of automatic failure.
- Treating the ASR as a formality. Vague or unevidenced responses get flagged at theoretical review; better to catch gaps yourself first.
- Leaving evidence gathering until the audit date. The ASR and evidence pack need to be complete before the audit can start, not during it.
- Forgetting the annual attestation. A three-year certificate still requires you to reconfirm your position every year.
Level 1 Assessment Checklist
Before the audit — on you:
- Valid Cyber Essentials certificate in place, with scope overlapping your DCC scope
- DCC scope documented and defensible, including any non-internet-connected systems
- Certification Body engaged and ASR issued
- All 101 controls answered in the ASR, with evidence referenced and hashed
- Evidence folder complete and access shared with your assessor
During and after — on your assessor, with your input:
- Audit dates confirmed, and kickoff call attended
- Any clarification actions from the readiness check resolved
- Evidence retention plan in place for 3.5 years
Get in Touch
Periculo is an IASME-authorised Certification Body, delivering DCC assessments at every level. If you're preparing for a Level 1 assessment, or you're not yet sure which level applies to your contracts, get in touch, and we'll talk you through it.